Who else looked this up?

Every lookup under log.dnsp.co is recorded, whatever transport carried it. Enter the label you used and the addresses that resolved it come back here, with no need for TCP.

.log.dnsp.co
How to use it
  1. Pick a label nobody could guess and resolve it once, from wherever you want to test.
  2. Wait. If your traffic is being watched, something else will resolve the same label.
  3. Come back, enter the label here, and see every address that asked for it.

Records are kept until the next database wipe. A label you have used before will carry its older hits too.

FIG. 05: Addresses that resolved it

Enter a label on the left. Anything already resolved under log.dnsp.co will be listed here.

Reading this

Several addresses in the same block are usually one resolver fleet asking from different egress points, not several observers. Addresses from an unrelated network are the interesting ones.

Build a log query